CVE-2026-29133 impacts SEPPmail Secure Email Gateway versions before 15.0.3, enabling an attacker to upload PGP keys with User IDs that do not correspond to their email address. This medium-severity vulnerability carries a CVSSv4 score of 5.3, featuring a low attack complexity and network vector, primarily posing a low integrity risk through potential email spoofing or misattribution. There is currently no evidence of active exploitation, no public exploit code available, and community discussion surrounding this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.3CPE matchmatch criteria | cpe:2.3:a:seppmail:secure_email_gateway:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.